3 ms·
the only way to bypass PIN would be an actual backdoor in Bitlocker. no way around that. an actual backdoor in microsoft encryption was never documented, and th
by aiscoming 5mo ago
the only way to bypass PIN would be an actual backdoor in Bitlocker. no way around that. an actual backdoor in microsoft encryption was never documented, and there are Snowden documents showing FBI pressing Microsoft into introducing one and Microsoft refusing
so I call bullshit on the PIN bypass
- cookiengineer 5mo ago> the only way to bypass PIN would be an actual backdoor in Bitlocker. no way around that. an actual backdoor in microsoft encryption was never documented, and there are Snowden documents showing FBI pressing Microsoft into introducing one and Microsoft refusing A USB stick containing a masterkey to decrypt a bitlocker volume is literally the definition of a backdoor. Go on, try it out. It works.
- aiscoming 5mo agono, to access a bitlocker volume which automatically decrypts thats an LPE, not an encryption backdoor the USB stick doesnt decrypt bitlocker, it just gives you root after bitlocker was AUTOMATICALLY decrypted
- cookiengineer 5mo ago> no, to access a bitlocker volume which automatically decrypts > thats an LPE, not an encryption backdoor No. RedSun and Bluehammer were LPEs > the USB stick doesnt decrypt bitlocker, it just gives you root after bitlocker was AUTOMATICALLY decrypted No, that's not what the bypass does. Maybe go try it out and verify it before you come to your quickly made conclusions? It's not tied to "automatically decrypted" volumes, whatever that would imply for your setup requiring a pretty pointless TPM keystore for that. If your case were true, it would also imply that any bitlocker cryptography never really worked because it was automatically decryptable without the need for a password/hash/whatever to get your keys from the keystore, which actually makes it so much worse. Even worse than the previously known coldboot attacks.
- aiscoming 5mo agoits pretty obvious you have no idea how bitlocker works, and its various modes - TPM only, TPM+PIN, PIN only
- cookiengineer 5mo ago> its pretty obvious you have no idea how bitlocker works, and its various modes - TPM only, TPM+PIN, PIN only How could anybody besides a Microsoft employee, given the appearance of this bypass technique?
- mananaysiempre 5mo agoLinux can decrypt BitLocker-encrypted drives. The cryptography is known and solid. The issue is that, as 'aiscoming says, its surroundings in Windows make the quality of the cryptography irrelevant. In the default BitLocker configuration, Windows puts all the key material in the TPM, locked behind the usual trusted-boot stuff: known-good BIOS hashes the bootloader and tells the TPM, bootloader hashes the kernel and tells the TPM, kernel hashes the initial process and tells the TPM, (I’m not sure how far it goes in this specific application,) and at the end of it the TPM won’t release the keys unless the entire chain was correct. This process does (modulo TPM flaws) ensure the disk will only be decryptable when in the original computer running the original OS. It does not ensure that the original OS will not subsequently give a root shell to anyone who walks up to the keyboard and types in a cheat code, and that’s essentially what’s happening here. Celebrite et al. take a similar approach: after your Android phone boots and you first enter your PIN (which, unlike with BitLocker defaults, is required to unlock the TPM, thus the distinguished status of “before first unlock” aka BFU vs “after first unlock” aka AFU), the key material is already in RAM and breaking dm-crypt is not necessary; all that’s needed is find a USB stack vulnerability or a Bluetooth stack vulnerability or whatnot that can be leveraged into a root shell.
- ndiddy 5mo agoNote that Microsoft did take the “Linux can decrypt drives in TPM-only” scenario into account. If any UEFI settings are changed related to stuff like boot order, the computer is supposed to see that the settings have changed and require the recovery password to unlock the volume. Knowing the quality of vendor firmware implementation, I’m not sure how well this works in practice. Agreed that the default Bitlocker config is much less secure than having a PIN at boot time due to the amount of code that gets run.
- stephbook 5mo agoSmells like a compromise. Microsoft enables BitLocker by default, thus protecting companies and users at scale. But the price is a backdoor they hope noone finds. Someone else claimed this doesn't affect people who actually care about security and enable boot-time password protection.
- ranger_danger 5mo agoYou're assuming the PIN was ever connected to the key itself in the first place. We don't know how that mechanism works, it could just be a totally separate gate that IS bypassable.
- bri3d 5mo agoWe can just do research to figure that out? The recent trend towards conspiracy theories against things that are trivially discoverable is so frustrating. https://post-cyberlabs.github.io/Offensive-security-publications/posts/2024_09_tpmandpin/ https://post-cyberlabs.github.io/Offensive-security-publicat... https://blog.scrt.ch/2024/10/28/privilege-escalation-through-tpm-sniffing-when-bitlocker-pin-is-enabled/ https://blog.scrt.ch/2024/10/28/privilege-escalation-through... Yes, the PIN is entangled with the key material.
- pregnenolone 5mo ago> The recent trend towards conspiracy theories against things that are trivially discoverable is so frustrating. So true.
- ranger_danger 5mo agoThe article shows that the PIN-entangled key material can still be downloaded directly from the TPM. This means it's vulnerable to an offline bruteforce attack to derive the PIN. So it's still doable, even in an automated fashion, just slower. With today's multi-GPU cloud systems available to everyone with a credit card, you can probably crack the default-length 6-digit PIN the same day you extract the key protector.
- bri3d 5mo agoI'm glad we were able to move past "We don't know how that mechanism works, it could just be a totally separate gate that IS bypassable" and into the actual way the mechanism works! > The article shows that the PIN-entangled key material can still be downloaded directly from the TPM. Not exactly, the TPM has PolicyAuthValue(PIN), so the PIN also needs to be provided to the TPM to unseal the material, and the hardware anti-hammering should prevent brute forcing it this way. The blog post documents dumping the PIN-entangled key material by MITM-ing the TPM communication while a user enters the PIN; the entanglement is a belt-and-suspenders approach.